Skip to content

Top Stories

Top Stories

Primary Menu
  • Breaking News
  • UNIT CONVERTER
  • QR Code Generator
  • SEO META TAG GENERATOR
  • Background Remover Tool
  • Image Enhancer Tool
  • Image Converter Tool
  • Image Compressor Tool
  • Keyword Research Tool
  • Paint Tool
  • About Us
  • Contact Us
  • Privacy Policy
HOME PAGE
  • Home
  • Uncategorized
  • Azure API Vulnerabilities Expose VPN Keys and Grant Over-Privileged Access via Built-In Roles
  • Uncategorized

Azure API Vulnerabilities Expose VPN Keys and Grant Over-Privileged Access via Built-In Roles

VedVision HeadLines July 3, 2025
Azure API Vulnerabilities Expose VPN Keys and Grant Over-Privileged Access via Built-In Roles


Token Security experts recently conducted a thorough investigation that exposed serious security weaknesses in Microsoft Azure’s Role-Based Access Control (RBAC) architecture.

Azure RBAC, the backbone of permission management in the cloud platform, allows administrators to assign roles to users, groups, or service principals with predefined permissions at varying scopes, from entire subscriptions to specific resources.

However, the investigation unearthed that several built-in roles intended to provide limited, service-specific access are misconfigured with excessive privileges.

Roles such as Managed Applications Reader and Log Analytics Reader, among a total of 10 identified, grant the overly broad */read permission, effectively mirroring the generic Reader role.

Azure API Vulnerabilities
Role assignment

This allows access to sensitive metadata across all Azure resources, far beyond what their descriptions suggest.

Such over-privileging can enable attackers to extract credentials from automation accounts, map network configurations for further exploitation, and uncover critical data in storage accounts or backup vaults, creating a fertile ground for privilege escalation and attack planning.

Exploiting Azure API to Leak VPN Pre-Shared Keys

Compounding the issue, researchers discovered a severe vulnerability in the Azure API that permits the leakage of VPN Gateway pre-shared keys (PSKs) using only read permissions.

Typically, Azure enforces permissions through HTTP method distinctions read-only operations use GET, while sensitive data retrievals are safeguarded with POST requests to block unauthorized access.

However, an oversight in the API design led to the VPN connection shared key retrieval being implemented as a GET request, bypassing intended security controls.

This flaw allows an attacker with minimal read access, often obtained via the aforementioned over-privileged roles, to fetch the PSK for Site-to-Site (S2S) VPN connections.

Armed with this key, a malicious actor could establish a rogue connection, gaining unauthorized entry to internal cloud assets, virtual private clouds (VPCs), and even on-premises networks linked through the Azure VPN Gateway.

This vulnerability transforms a seemingly innocuous read permission into a gateway for deep network infiltration, particularly devastating in hybrid environments where cloud and on-premises systems intersect.

Microsoft’s Response

Upon disclosure, Microsoft classified the over-privileged roles as a ‘low severity’ issue, opting to update documentation rather than restrict the roles’ permissions, leaving organizations exposed to potential misuse.

Conversely, the VPN PSK leak was deemed ‘Important,’ prompting a swift fix by mandating a specific permission (Microsoft.Network/connections/sharedKey/action) for key access, alongside a $7,500 bounty awarded to the researcher.

To safeguard against these threats, organizations must proactively audit and restrict the use of the identified over-privileged roles, replacing them with custom roles tailored to minimal necessary permissions.

Limiting role scopes to specific resources or resource groups, rather than broad subscriptions, further reduces risk.

As cloud security remains a shared responsibility, this incident underscores the need for vigilance blind trust in provider tools can lead to catastrophic breaches.

For robust protection, continuous monitoring and validation of permissions are essential to prevent identity-driven attacks in Azure environments.

Exclusive Webinar Alert: Harnessing Intel® Processor Innovations for Advanced API Security – Register for Free



Source link

Continue Reading

Previous: S&P 500, Nasdaq close at records on jobs data; Nvidia market cap nears $4 trillion – Reuters
Next: California Leads Charge on AI Regulation

Related News

US risks financial crisis ahead of midterm elections: former IMF official
  • Uncategorized

US risks financial crisis ahead of midterm elections: former IMF official

VedVision HeadLines July 13, 2025
Will It Blast Through 5,000 Or Slip Back To 0,000?
  • Uncategorized

Will It Blast Through $125,000 Or Slip Back To $110,000?

VedVision HeadLines July 13, 2025
Bitcoin May Land On 36 More Company Balance Sheets This Year, Blockchain Firm Says
  • Uncategorized

Bitcoin May Land On 36 More Company Balance Sheets This Year, Blockchain Firm Says

VedVision HeadLines July 13, 2025

Recent Posts

  • The changing landscape of employment
  • US risks financial crisis ahead of midterm elections: former IMF official
  • Kate Middleton presents trophy to Jannik Sinner after he ended Carlos Alcaraz’s Wimbledon reign
  • Saina Nehwal announces separation from husband Parupalli Kashyap
  • Will It Blast Through $125,000 Or Slip Back To $110,000?

Recent Comments

No comments to show.

Archives

  • July 2025
  • June 2025
  • May 2025
  • April 2025

Categories

  • Current Affairs
  • Shopping
  • Uncategorized

You may have missed

The changing landscape of employment
  • Current Affairs

The changing landscape of employment

VedVision HeadLines July 13, 2025
US risks financial crisis ahead of midterm elections: former IMF official
  • Uncategorized

US risks financial crisis ahead of midterm elections: former IMF official

VedVision HeadLines July 13, 2025
Kate Middleton presents trophy to Jannik Sinner after he ended Carlos Alcaraz’s Wimbledon reign
  • Current Affairs

Kate Middleton presents trophy to Jannik Sinner after he ended Carlos Alcaraz’s Wimbledon reign

VedVision HeadLines July 13, 2025
Saina Nehwal announces separation from husband Parupalli Kashyap
  • Current Affairs

Saina Nehwal announces separation from husband Parupalli Kashyap

VedVision HeadLines July 13, 2025
Copyright © All rights reserved. | MoreNews by AF themes.